ComboFix 08-10-11.02 - Administrator 2008-10-11 22:58:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.932.81.1033.18.696 [GMT 9:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\Adobe\crc.dat
C:\Documents and Settings\Administrator\Favorites\Download programs.url
C:\Documents and Settings\Administrator\Favorites\Games.url
C:\Documents and Settings\Administrator\Favorites\Translator.url
C:\Documents and Settings\Administrator\Favorites\Videos.url
C:\Documents and Settings\Administrator\Start Menu\Programs\Download programs.url
C:\Documents and Settings\Administrator\Start Menu\Programs\Games.url
C:\Documents and Settings\Administrator\Start Menu\Programs\Translator.url
C:\Documents and Settings\Administrator\Start Menu\Programs\Videos.url
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\setup.exe
----- BITS: Possible infected sites -----
hxxp://78.157.143.163
hxxp://78.157.142.26
.
((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
.
2008-10-11 15:28 . 2008-10-11 15:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 15:28 . 2008-10-11 15:28 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-10-11 15:28 . 2008-10-11 15:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-10-11 15:28 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 15:28 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-09 15:55 . 2008-10-09 15:55 <DIR> d-------- C:\WINDOWS\logs
2008-10-09 15:55 . 2008-10-09 16:05 <DIR> d-------- C:\Program Files\AppRanger
2008-10-09 15:55 . 2008-10-09 16:05 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\AppRanger
2008-10-09 15:50 . 2008-10-09 15:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-09 07:51 . 2008-10-09 07:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt
2008-10-09 07:51 . 2008-10-09 07:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sunbelt
2008-10-09 07:48 . 2008-10-09 07:48 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-10-09 06:28 . 2008-10-09 06:28 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
2008-10-09 06:28 . 2008-10-09 06:28 385 --a------ C:\WINDOWS\system32\user_gensett.xml
2008-10-09 06:10 . 2008-10-09 06:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\True Sword
2008-10-09 06:09 . 2008-10-09 15:45 <DIR> d-------- C:\Program Files\True Sword 5
2008-10-09 02:56 . 2008-10-09 02:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LogoMaker
2008-10-09 02:54 . 2008-10-09 02:54 <DIR> d-------- C:\Program Files\Studio V5
2008-10-09 01:01 . 2008-10-09 01:01 <DIR> d-------- C:\Program Files\Alwil Software
2008-10-08 04:16 . 2008-10-09 00:00 <DIR> d--h----- C:\$AVG8.VAULT$
2008-10-08 04:11 . 2008-10-09 00:58 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-09-21 04:45 . 2008-09-21 04:47 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-09-21 04:27 . 2008-09-21 04:27 <DIR> d-------- C:\Program Files\Softwin
2008-09-14 05:22 . 2008-09-14 13:09 121 --a------ C:\WINDOWS\bdagent.INI
2008-09-14 05:02 . 2008-10-09 04:46 <DIR> d-------- C:\Program Files\BitDefender
2008-09-14 05:01 . 2008-10-09 07:59 <DIR> d-------- C:\Program Files\Common Files\BitDefender
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 13:47 --------- d-----w C:\Program Files\Steam
2008-10-08 16:24 --------- d-----w C:\Program Files\Off Road Arena
2008-10-07 18:56 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-09-20 19:27 --------- d-----w C:\Program Files\Common Files\Softwin
2008-09-18 14:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-09-14 18:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\dvdcss
2008-09-12 13:47 138,280 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-12 13:47 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-09-06 10:10 --------- d-----w C:\Program Files\Java
2008-08-11 15:06 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
2008-04-23 14:35 20 ---h--w C:\Documents and Settings\All Users.WINDOWS\Application Data\PKP_DLdu.DAT
2006-12-03 08:11 1,557 ----a-w C:\Documents and Settings\Administrator\bpk.dat
2006-12-02 05:30 1,258 ----a-w C:\Documents and Settings\Administrator\web.dat
2001-09-28 08:00 164,864 ------w C:\Program Files\UNWISE.EXE
.
------- Sigcheck -------
2006-04-20 20:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 21:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2004-08-04 21:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-04 21:00 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-10-08 1410296]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 165784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-14 7323648]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-14 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"M-Audio Taskbar Icon"="C:\WINDOWS\System32\DeltaIITray.exe" [2007-12-03 236040]
"DeltaIITaskbarApp"="C:\WINDOWS\system32\DeltaIITray.exe" [2007-12-03 236040]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2005-12-14 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-05-15 479232]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-08-07 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2007-04-12 10640]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);C:\WINDOWS\system32\DRIVERS\deltaII.sys [2007-12-03 297992]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys [ ]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-10-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RASOA - C:\WINDOWS\msn64.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gz1o1pf2.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-11 23:01:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-11 23:04:10
ComboFix-quarantined-files.txt 2008-10-11 14:03:32
Pre-Run: 5,255,548,928 bytes free
Post-Run: 5,226,393,600 bytes free
158 --- E O F --- 2007-08-17 06:36:54